By sending specially constructed packets across the wire a malicious remote attacker could cause tcpdump to crash or potentially run arbitrary code as the user under which tcpdump was being run.
A heap overflow vulnerability has been discovered in all versions of rsync prior to 2.5.7. This vulnerability, exploitable when rsync is being run in "server mode", may allow the attacker to run arbitrary code on the compromised server.
A cache poisoning vulnerability exists in the version of BIND shipped with all versions of EnGarde Secure Linux. Successful exploitation of this vulnerability may result in a temporary denial of service until the bad record expires from the cache.
A buffer overflow in mod_alias and mod_rewrite was discovered in the Apache web server. This vulnerability may be exploited when a regular expression with more then nine captures is defined in either the httpd.conf or an .htaccess file.